Tunnels — expose a local port on a public {name}.maxoperf-tunnel.com URL
A tunnel exposes a port on your machine (or anywhere else something is listening) on a public, TLS-terminated URL: https://<name>.maxoperf-tunnel.com. It is MaxoPerf’s reverse-tunnel service, in the same family as ngrok, and it is completely free on every plan. MaxoPerf never bills tunnels, on any tier.
npx @maxoperf/tunnel http 3000✔ guest tunnel online https://swift-otter-7f3.maxoperf-tunnel.com → http://127.0.0.1:3000That is the whole zero-signup path: no account, no API key, no config file. See Create a tunnel for the full CLI, console, and API flows.
Why you’d use one
Section titled “Why you’d use one”- Show someone a local build. Point a teammate, a client, or a webhook provider at a URL that reaches your laptop.
- Test webhooks against a local server. Stripe, GitHub, or any provider that needs a public callback URL can hit your tunnel and forward straight to your local dev server.
- Expose a MaxoPerf virtual service or run for external access without deploying it anywhere else first.
- Quick demos. A tunnel URL is live as soon as the CLI connects. No deploy pipeline.
Guest mode vs. an account tunnel
Section titled “Guest mode vs. an account tunnel”| Guest mode | Account tunnel | |
|---|---|---|
| Setup | npx @maxoperf/tunnel http <port>, nothing else | Create via console/API/MCP first, then run the CLI with its token |
| Subdomain | Auto-generated (e.g. swift-otter-7f3), stable across runs on the same machine | You choose the name (<name>.maxoperf-tunnel.com) |
| Concurrent tunnels | 1 | 10 on the free tier, up to 200 on Pro, unlimited on Enterprise |
| Security & Interstitial | Anti-phishing warning screen for browser visitors (bypassable) | Direct connection (zero interstitial) |
| Access controls (IP allow/deny, basic/bearer auth, rate limit) | Fixed, safe defaults; not configurable | Fully configurable |
| Request capture (headers/body, for the inspector + replay) | Off | Configurable (headers or headers+body) |
| Idle timeout | Fixed at 1 hour | Configurable (default 1 hour) |
The guest identity is a durable token the CLI saves locally (~/.maxoperf/tunnel.json, file mode 0600), so re-running the CLI on the same machine reuses the same URL every time. That lasts until you claim it into an account or it expires. Claiming keeps the URL and turns on the account-tunnel features above, with no downtime.
Anti-phishing security protection
Section titled “Anti-phishing security protection”Anonymous guest tunnels show a security interstitial before they forward browser traffic. It protects visitors from credential theft and protects MaxoPerf’s domain reputation against automated blacklists (e.g., Google Safe Browsing):
- Browser warning: When a visitor opens an anonymous guest tunnel in a web browser, they see an unverified developer warning:
“You are visiting a developer reverse tunnel hosted through MaxoPerf. Never enter passwords, credit cards, or personal credentials on this page.”
- One-click proceed: Visitors acknowledge the notice by clicking Proceed to Developer Tunnel. This sets a session cookie (
__mptt_skip_warning=1) and forwards them to the destination application right away. - Bypass for APIs and automated tools: Non-browser clients and automated workflows can skip the warning without receiving any HTML:
- Add the header
X-MaxoPerf-Skip-Browser-Warning: 1(orngrok-skip-browser-warning: 1for drop-in compatibility with existing scripts). - Standard non-browser
User-Agentstrings (such ascurl, API clients, SDKs, webhooks, and automated test runners) bypass the interstitial automatically.
- Add the header
- Authenticated account tunnels: Tunnels that authenticated MaxoPerf accounts create never display an interstitial screen. Traffic connects directly.
What every tunnel gets
Section titled “What every tunnel gets”- Real TLS, terminated at the edge with automated wildcard certificates. Account tunnels show no interstitial.
- WebSocket and SSE pass straight through. A websocket-based dev server or a streaming endpoint works through the tunnel unchanged.
- Automatic reconnect. If your local network drops, the CLI reconnects with backoff and the tunnel comes back online on the same URL.
- Full traffic statistics: request counts, error rates, latency percentiles, and bytes in/out, on a live timeline (account tunnels; see Create a tunnel).